Hi Team,
I am getting Rule message-0 for many events and for many data sources in SIEM. When I am clicking on show rule -- it shows "Error not found".
Kindly help how to edit that rule so that i can get Rule message name.
Thanks in advance.
Regards,
You may want to look at KB83649 "SIEM rule message names appear as '0' after a rule purge":
https://kc.mcafee.com/corporate/index?page=content&id=KB83649&snspd-0115
My not be applicable but could give you some leads.
cheers,
Andrew
Hi,
Probably the rule which you are looking for was deleted. In the most cases 0 in the rule name appear only then the data source (or auto learn) rule was deleted/purged. it will be visible again when the logs come to your system and parsed with the same asp rule which correspond to the deleted rule - also all rule names will change the name to proper data source rule.
But off course you must have proper asp rule...
Regards
MK
Hi MK,
Thanks for your reply.
Is there any way to configure data source rule so that it start parsing again.
Also logs are coming as Rule message as 0 for many data sources.
Need your help in resolving this issue as I am new in Nitro SIEM.
Thanks...
I've run into this recently, We found that it was related to the policy and roll-out status. we had rules titled 0, the partial names, and finally the full name after some updates. Tried a manual rule update and that seemed to resolve our issue.
Nice to hear that
Regards
MK
Hi,
Thanks for reply.
I tried doing manual rule updates and rolled out the policy.
But no luck.
Regards,
I've just run into the 0 rule name again, it was definitely incremental and consistent with a rule updates, but we did find some missing rules, Im not sure if the two sets of symptoms are related.
Hi Andrew and MK,
Thanks for the reply.
@ MK,
Is there any way to configure data source rule so that it start parsing again.
Also logs are coming as Rule message as 0 for many data sources.
Need your help in resolving this issue as I am new in Nitro SIEM.
Thanks...
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA